CVE Vulnerabilities

CVE-2015-6316

Published: Nov 06, 2015 | Modified: Jan 06, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The default configuration of sshd_config in Cisco Mobility Services Engine (MSE) through 8.0.120.7 allows logins by the oracle account, which makes it easier for remote attackers to obtain access by entering this accounts hardcoded password in an SSH session, aka Bug ID CSCuv40501.

Affected Software

Name Vendor Start Version End Version
Mobility_services_engine Cisco 5.1_base (including) 5.1_base (including)
Mobility_services_engine Cisco 5.2_base (including) 5.2_base (including)
Mobility_services_engine Cisco 6.0_base (including) 6.0_base (including)
Mobility_services_engine Cisco 7.0_base (including) 7.0_base (including)
Mobility_services_engine Cisco 7.4.100.0 (including) 7.4.100.0 (including)
Mobility_services_engine Cisco 7.4.110.0 (including) 7.4.110.0 (including)
Mobility_services_engine Cisco 7.4.121.0 (including) 7.4.121.0 (including)
Mobility_services_engine Cisco 7.4_base (including) 7.4_base (including)
Mobility_services_engine Cisco 7.5.102.101 (including) 7.5.102.101 (including)
Mobility_services_engine Cisco 7.6.100.0 (including) 7.6.100.0 (including)
Mobility_services_engine Cisco 7.6.120.0 (including) 7.6.120.0 (including)
Mobility_services_engine Cisco 7.6.132.0 (including) 7.6.132.0 (including)
Mobility_services_engine Cisco 8.0(110.0) (including) 8.0(110.0) (including)
Mobility_services_engine Cisco 8.0_base (including) 8.0_base (including)

References